Assertion Occasionally Signed with Incorrect Cert

Cantor, Scott cantor.2 at osu.edu
Fri Aug 16 13:16:05 EDT 2013


On 8/16/13 12:24 PM, "Mark Valites" <mvalites at buffalo.edu> wrote:
>
>We sign new SP certs with our internal CA all the time here, but rarely
>(if ever) do the SPs update their keys/submit a new CSR - after wondering
>about this more, I went back & read the NativeSPMultipleCredentials page.
>I configured the CredentialResolver to chain together the old/new
>cert/keys & do the key rollover properly & now it works as expected. I'm
>a bit surprised we haven't had an SP do this previously.

You can also manipulate the metadata with the KeyDescriptor use attribute,
and that can change the process. The instructions I wrote specifically
were designed to avoid having to do that, but it's not the only way.

But it's a very precise process no matter what approach is used, and
literally one mistake will break it at some point.

-- Scott




More information about the users mailing list